Jobs and Careers
TI

Lead Third-Party Cyber Risk Analyst

TIAA
United Statesfull_timeVerifiedPosted 20 Dec 2024
💰 $167,100/yr($104,100/yr$167,100/yr)

About the role

Lead Third-Party Cyber Risk Analyst

 

TIAA is seeking a Lead Third-Party Cyber Risk Analyst to support their Enterprise Cybersecurity program. This role will conduct and evaluate third party risk assessments covering cyber security, identify information security risks, document issues, identify remediation action plans, and collaborate with internal partners and third parties to mitigate the issues. This is a lead role within the team and will be assigned special projects within Cybersecurity or Third-Party Cyber Risk Management as well as provide Quality Assurance of assessments within the team.

 

This role will be a key member of our Governance & Risk organization within our Cybersecurity organization. The ideal candidate will have experience within the Cyber Security field, with a focus on Governance, Risk & Compliance. In addition, possess an in-depth understanding of Third-Party Cyber Risk Management practices and experience providing guidance to internal partners. This role requires strong communications skills, both oral and written, with excellent interpersonal, team and organizational skills. The ideal candidate must be able to execute small projects by understanding a problem statement, identifying solutions, and completing the work as part of our Agile team. 

 

This role works under limited supervision and will also support the overall program and process execution of the vendor risk management team and to drive improvements to minimize risk exposure to the organization.



Key Responsibilities and Duties

  • Exhibits a deep understanding of Third-Party Cyber Risk Management practices and provides guidance to internal partners as required.
  • Complete Third-Party Cyber Risk assessments to identify risks and validate implemented security controls to mitigate those risks.
  • Develop and maintain effective relationships with both internal/external stakeholders.
  • Collaborate with internal teams and third-party resources to communicate gaps identified through the assessment and provides recommendations to close the gaps.
  • Document and create issues in the Issue Management system and collaborate with external partners to drive remediation of the risks.
  • Demonstrate effective communication skills to collaborate with representatives of the Lines- of-Business, technology areas, risk partners, and vendors in performing their role.
  • Demonstrates ability to identify issues, develop plans to resolve, and understands how to escalate when needed.
  • Collaborate with technology and risk partners to create remediation action plans to mitigate cybersecurity risks and govern action plans through until completion.
  • Apply critical thinking to situations where incomplete / imperfect information is available.
  • Facilitate implementation of the Cyber organization’s global strategies and initiatives to enhance Information Technology plans, operations, and procedures.
  • Collaborate across extended teams to identify optimization opportunities and drive efficiencies within the vendor engagement and vendor due diligence processes.
  • Maintain and enhance documented policies and procedures.

Educational Requirements

  • University (Degree) Preferred

Work Experience

  • 5+ Years Required; 7+ Years Preferred

Physical Requirements

  • Physical Requirements: Sedentary Work


Career Level
8IC

Qualifications:

Required:

  • Minimum of 5+ years’ experience working in a similar Third-Party Cyber Risk Management role. Possess direct experience with risk assessment methodologies, risk mitigation strategies, and risk reporting.
  • Minimum of 5+ years’ experience interfacing and communicating (both verbal and written) with both technical and non-technical stakeholders on articulating risks, mitigation plans, and compliance requirements.
  • Possess the ability to break down strategic problems, analyze data, develop a remediation approach, communicate recommendations, and drive work effort to successful completion.
  • Knowledge of the NIST Risk Management Framework (RMF) and security controls. Must understand the risk management process, risk mitigation, and risk tracking.

Preferred:

  • Minimum of 7+ years of experience working in a similar role.
  • Knowledge of new/emerging practices within cybersecurity and controls.

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

TIAA

View company profile →